OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.
| Software | From | Fixed in |
|---|---|---|
| openbase_international_ltd / openbase | 7.0.15 | 7.0.15.x |
| openbase_international_ltd / openbase | - | 10.0.x |
| openbase_international_ltd / openbase | 9.1.5 | 9.1.5.x |
| openbase_international_ltd / openbase | 8.0.4 | 8.0.4.x |
| apple / xcode | - | 2.2.x |